为远程老年护理系统设计符合GDPR的安全架构:一种设计即隐私的方法
Designing a GDPR-Compliant Security Architecture for Remote Elderly Care Systems: A Privacy-by-Design Approach
浏览论文内容
中文总结 AI 辅助
研究基于物联网的远程老年护理系统安全架构问题,提出SEG框架,通过ESP32-WROOM-32网关实现多项安全措施,经多种验证方式证明该框架能兼顾GDPR合规与运营效率,解决三方差距问题。
中文摘要 AI 辅助
基于物联网的远程老年护理系统会产生大量敏感健康数据,但现有安全架构尚未同时解决三个相互依存的挑战:符合GDPR的边缘层假名化、作为约束性架构约束的老年人特定零交互可用性,以及在单一统一设计中基于STRIDE的集成威胁验证。本文提出了安全边缘网关(SEG)框架,这是一种经过软件模拟验证的集成物联网安全架构,旨在同时解决这三方差距的所有三个方面。一个ESP32-WROOM-32住宅网关执行MAC地址白名单、在任何网络传输之前进行HMAC-SHA256加密假名化、AES-128-CBC有效载荷加密以及TLS 1.3传输安全,符合GDPR第25条和第32条。该框架通过基于软件的模拟、对所有六个类别进行全面的STRIDE威胁建模、攻击树分析、针对九项监管义务的GDPR合规映射以及第35条下的数据保护影响评估(DPIA)进行验证。已发布的基准测试证实,在可比的物联网部署中,MQTT比HTTP能耗低6-8%,边缘处理实现了低于50毫秒的响应延迟,而仅云系统的响应延迟为200-700毫秒。结果表明,在资源受限的老年护理物联网部署中,GDPR合规性和运营效率是互补而非相互竞争的目标。
英文摘要
IoMT-based remote elderly care systems generate continuous streams of sensitive health data, yet existing security architectures have not simultaneously addressed three interdependent challenges: GDPR-compliant edge-layer pseudonymisation, elderly-specific zero-interaction usability as a binding architectural constraint, and integrated STRIDE-based threat validation within a single unified design. This paper presents the Secure Edge Gateway (SEG) framework - a software-simulation-validated integrated IoMT security architecture for elderly care designed to resolve all three dimensions of this tripartite gap simultaneously. An ESP32-WROOM-32 residential gateway enforces MAC address whitelisting, HMAC-SHA256 cryptographic pseudonymisation before any network transmission, AES-128-CBC payload encryption, and TLS 1.3 transport security, in compliance with GDPR Articles 25 and 32. The framework is validated through software-based simulation, full STRIDE threat modelling across all six categories, attack tree analysis, GDPR compliance mapping across nine regulatory obligations, and a Data Protection Impact Assessment (DPIA) under Article 35. Published benchmarks confirm MQTT consumes 6-8% less energy than HTTP in comparable IoT deployments, and edge processing achieves sub-50 ms response latency versus 200-700 ms for cloud-only systems. The results demonstrate that GDPR compliance and operational efficiency are complementary - not competing - objectives in resource-constrained IoMT deployments for elderly care.